H3C MSR1000[2600][3600] Routers Configuration Examples All-in-One-R9141-6W100

HomeSupportConfigure & DeployConfiguration ExamplesH3C MSR1000[2600][3600] Routers Configuration Examples All-in-One-R9141-6W100
Table of Contents
Related Documents
60-Client-Initiated L2TP Tunnel Configuration Examples

H3C Routers

Client-Initiated L2TP Tunnel Configuration Examples

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Copyright © 2024 New H3C Technologies Co., Ltd. All rights reserved.

No part of this manual may be reproduced or transmitted in any form or by any means without prior written consent of New H3C Technologies Co., Ltd.

Except for the trademarks of New H3C Technologies Co., Ltd., any trademarks that may be mentioned in this document are the property of their respective owners.

The information in this document is subject to change without notice.



Introduction

The following information provides client-initiated L2TP tunnel configuration examples.

Prerequisites

The following information applies to Comware 9-based router. Procedures and information in the examples might be slightly different depending on the software or hardware version of the routers.

The configuration examples were created and verified in a lab environment, and all the devices were started with the factory default configuration. When you are working on a live network, make sure you understand the potential impact of every command on your network.

The following information is provided based on the assumption that you have basic knowledge of L2TP.

Example: Configuring a client-initiated L2TP tunnel

Network configuration

As shown in Figure 1, Host accesses the corporate network through an L2TP tunnel. Configure the LNS to actively accept tunnel setup requests from Host and set up an L2TP tunnel.

Figure 1 Network diagram

Analysis

For a valid user to access normally and establish an L2TP tunnel in client-Initiated mode, perform the following tasks:

1.     Configure L2TP user-side authentication on the LNS.

2.     Create a PPP user and create a domain for the user.

3.     Initiate tunnel setup requests on Host by using the username configured on the device.

Software versions used

This configuration example was created and verified on R9141P16 of the MSR2630E-X1 device.

Procedures

Configuring the LNS

# Configure interface GigabitEthernet 1/0/1.

<LNS> system-view

[LNS] interface gigabitethernet 1/0/1

[LNS-GigabitEthernet1/0/1] ip address 1.1.1.1 24

[LNS-GigabitEthernet1/0/1] quit

# Create a PPP user with the username as user and password as hello.

[LNS] local-user user class network

[LNS-luser-network-user] password simple hello

[LNS-luser-network-user] service-type ppp

[LNS-luser-network-user] quit

# Create domain abc, and configure the domain to perform local authentication for users.

[LNS] domain abc

[LNS-isp-abc] authentication ppp local

[LNS-isp-abc] quit

# Enable L2TP.

[LNS] l2tp enable

# Create VT interface 1, and assign IP address 192.168.0.1/24 to the VT interface. Configure the PPP authentication method as CHAP on the VT interface, and specify the VT interface to allocate IP address 192.168.0.2 to the PPP user.

[LNS] interface virtual-template 1

[LNS-Virtual-Template1] ip address 192.168.0.1 24

[LNS-Virtual-Template1] ppp authentication-mode chap domain abc

[LNS-Virtual-Template1] remote address 192.168.0.2

[LNS-Virtual-Template1] quit

# Create L2TP group 1 in LNS mode, configure the local tunnel name as LNS, and specify VT interface 1 for receiving calls.

[LNS] l2tp-group 1 mode lns

[LNS-l2tp1] tunnel name LNS

[LNS-l2tp1] allow l2tp virtual-template 1

[LNS-l2tp1] undo tunnel authentication

[LNS-l2tp1] quit

Configuring Host

# Assign IP address 1.1.1.2 and gateway 1.1.1.1 to Host.

# Use Windows 7 as an example. Access Network and Sharing Center and click Set up a new connection or network.

Figure 2 Creating a network connection

 

# Select Connect to a workspace and click Next.

Figure 3 Selecting a connection option

 

# Select Use my Internet connection (VPN).

Figure 4 Selecting a connection method

 

# Set the Internet address, which is the address of the host-side interface on the LNS. Select the Don't connect now; just set it up so I can connect later option, and click Next.

Figure 5 Setting the LNS address

 

# In the diaglog box that opens, enter the username and password that have been configured on the device, and click Create.

Figure 6 Entering the username and password

 

# At this point, the connection is available. Click Close.

Figure 7 Connection established successfully

 

# Access the network connection page again, and you can see a new network connection named VPN Connection. Double-click it. The login window opens.

Figure 8 Newly generated connection

 

Figure 9 Login window

 

# Right-click the connection, and select Properties. The Properties dialog box opens.

Figure 10 VPN connection properties

 

# Click the Security tab. Select Optional encryption (connect even if no encryption) for data encryption and click OK.

Figure 11 Configuring security properties

 

# On the login window, enter username [email protected] and password hello configured on the router, and click Connect.

Figure 12 Connecting an L2TP tunnel

 

# Verify that the connection succeeded.

Figure 13 Connection succeeded

 

Verifying the configuration

# Verify that an L2TP tunnel has been established on the LNS.

[LNS] display l2tp tunnel

LocalTID RemoteTID State        Sessions RemoteAddress   RemotePort RemoteName

11556    1         Established  1        1.1.1.2         1701       Host

Configuration files

#

interface Virtual-Template1

 ppp authentication-mode chap domain abc

 remote address 192.168.0.2

 ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/1

 port link-mode route

 ip address 1.1.1.1 255.255.255.0

#

domain abc

 authentication ppp local

#

local-user aa class network

 password cipher $c$3$Rprc/RW4jluoNccTiRfV0t1OxEN0MegX

 service-type ppp

 authorization-attribute user-role network-operator

#

l2tp-group 1 mode lns

 allow l2tp virtual-template 1

 undo tunnel authentication

 tunnel name LNS

#

l2tp enable

#

Related documentation

·     Layer 2—WAN Access Configuration Guide in H3C MSR1000[2600][3600] Routers Configuration Guides (V9)

·     Layer 2—WAN Access Command Reference in H3C MSR1000[2600][3600] Routers Command References (V9)

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网